t-mobile[.]yftze[.]icu
“T-Mobile Tuesdays - Get Free Stuff & Great Deals | T-Mobile”
t-mobile.yftze.icu — Контент недоступний (HTTP 502). Уособлення бренду: Apple; Тип шахрайства: Tech Support Scam. Зведення доказів: VirusTotal 13/93 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 89/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
On 23 July 2026, investigators recorded the domain t-mobile.yftze.icu. The domain was registered on 21 February 2026 and immediately pointed to the IPv6 address 2a06:98c1:3120::3, which belongs to the Cloudflare network (AS13335) located in the United States. The site presented the page title “T‑Mobile Tuesdays – Get Free Stuff & Great Deals | T‑Mobile”, yet the underlying threat profile lists Apple as the impersonated brand and classifies the operation as a tech‑support scam. The SSL certificate is identified only as “WE1”, providing no additional validation of the issuer. Automated reputation services have assigned a Gridinsoft trust score of 0 out of 100, indicating a complete lack of trust.
VirusTotal analysis shows that 13 of 93 scanned security vendors flagged the domain, confirming malicious intent, and the domain appears on a single public blocklist. The PhishDestroy blocklist has already taken the domain offline, and current monitoring indicates the site is no longer reachable. Evidence confirms that the infrastructure relies on a shared Cloudflare edge, which complicates direct takedown but also offers a convenient vector for fast‑flux style hosting. The combination of a brand‑specific page title unrelated to the targeted brand, the tech‑support scam designation, and the low trust scores suggests the site was intended to lure victims into contacting purported support staff or to harvest credentials under the guise of Apple assistance.
However, the exact payload or credential‑capture mechanism has not been observed, and the site’s content beyond the title remains unverified. Defenders should continue to block the domain at DNS and proxy layers, monitor for any outbound connections to the listed IPv6 address, and add the domain to internal threat intelligence feeds.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога